Trezor Data Breach Larger Than First Reported: 67,000 More US Customers Affected
Key Takeaways
- •Trezor disclosed that an additional 67,000 U.S. customers had personal data leaked from orders placed between November 2019 and August 2021, on top of the 11,742 customers originally reported in August.
- •A further 1,947 customers had only their names, cities and email addresses exposed in the breach.
- •The leaked data came from Trezor's third-party fulfillment partner ShipMonk, which had falsely assured Trezor in writing that customer data had been deleted.
- •Trezor's parent company SatoshiLabs is investigating the incident, and affected customers were directly emailed when the breach was first disclosed.
- •The breach highlights a structural risk in the hardware wallet industry, where customer identity data is held by third-party shipping and payment providers outside the wallet maker's control.

Hardware wallet manufacturer Trezor has disclosed that a data breach first announced last month is worse than originally reported.
The Prague, Czech Republic-based company said on Friday that an additional 67,000 U.S. customers had their names, emails, phone numbers, shipping addresses and order numbers leaked. According to Trezor, the leaked data came from orders placed between November 2019 and August 2021. A further 1,947 customers had only their names, cities and emails exposed.
Trezor initially announced in August that data from 11,742 customers in the U.S., UK, Sweden, Colombia, Brazil, Italy, and Portugal had been exposed, with names, emails, phone numbers and shipping addresses leaked.
In a post on X, the company stated:
Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought. Another 67,000 customers from the US who ordered between November 2019 and August 2021…
— Trezor (@Trezor) September 4, 2026
In Friday's announcement, Trezor said that its third-party fulfillment partner, ShipMonk, had falsely reassured the company that customer data had been deleted.
"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications," Trezor wrote. "We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems."
The incident highlights a broader structural issue in the hardware wallet industry: even though hardware wallets are designed to keep private keys offline, the purchasing process typically runs through e-commerce platforms, payment processors and shipping providers that hold customers' personal identifying information. That means a customer's crypto holdings can remain secure on the device while their identity and contact details are exposed through third-party infrastructure outside the wallet maker's direct control.
Neither Trezor nor ShipMonk immediately responded to Bitcoin Magazine's questions.
When Trezor first disclosed the incident in August, it said the data had been leaked because ShipMonk experienced "unauthorized access to their systems containing customer data." The company added that it had directly emailed all customers involved in the breach. Trezor's parent company, SatoshiLabs, told Bitcoin Magazine last month that it was investigating the incident.
Trezor is one of the most popular Bitcoin hardware wallet solutions and also supports storing other cryptocurrencies.
Bitcoiners' personal data has been targeted by cybercriminals before, and leaked customer records have historically been used to target hardware wallet owners. Following the 2020 breach of competitor Ledger, affected customers received threatening text messages and phishing attempts that referenced their home addresses. In that incident, an unauthorized party accessed Ledger's e-commerce and marketing database, leaking over 1 million email addresses and the personal contact data of nearly 10,000 customers. At the start of this year, customers reported receiving emails from Global-e, Ledger's payment partner, saying that a data breach at its cloud systems leaked sensitive customer data.